Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Enforcement of monetary penalties.


In this instance the company can declare bankruptcy and the founders and investors can move on to their next gig - perhaps even throw a hapless developer to the authorities. Unless hippa somehow has special provisions. They need to go after the personal wealth of founders and investors to make this a serious crime.


That's the thing.

If HIPAA could pierce the corporate veil, this could no longer occur. Wanna dick around and not do your job as a founder / investor? Your personal assets are on the line.


I don't think this is the case. Last I read up you are personally liable for HIPAA violations. If you do something, knew it wasn't something you should do, and refused to fix it, stuff gets really bad.

To stay safe with medical data, however, you basically just need to hit whatever standard you think is reasonable. There's no established standards other than:

    1. "PII" encrypted during storage/transfer.
    2. Customers can request a download of their data.
    3. Customers can request you delete ALL their data.
    4. Fast track sec fixes above all other company goals.


Someone with a medical license and the legal ability to collect and secure data gave it to these clowns who clearly had no idea what they were doing.


My guess is the blame lies with insurers, probably keen to automate detection of "fraudulent whiplash claims" based on "the data". They'd get access to the records via their claims. This incident should show why sharing of data needs to be on a "need-to-share" basis by default if we want to have any hope of trying to stop this kind of thing in future.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: